logo

FileFix in the wild! New FileFix campaign goes beyond POC and leverages steganography

ID: e20493ed-51f0-571f-8ade-b77c55078568

STIX ID: report--e20493ed-51f0-571f-8ade-b77c55078568

Feed Name: TRU Security by Acronis

Threat Score
75/100

Date Published: 2025-09-16

Date Updated: 2026-07-24

...
...

**Executive summary:** Acronis TRU discovered a sophisticated FileFix phishing campaign (an evolution of ClickFix) using heavily obfuscated multilingual phishing pages and steganography to hide a second-stage PowerShell script and encrypted executables inside JPG images; the multistage chain culminates in a Go-based loader that deploys the StealC infostealer to harvest browsers, wallets, messaging apps and cloud credentials, with active indicators and global targeting observed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.